HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
COX ENTERPRISES, INC.
bd_8766c6dda720b44a · schema v1 · pii pii-v1
Full breach record for COX ENTERPRISES, INC. →Cox Enterprises, Inc. notified the New Hampshire Attorney General of a data security incident involving Oracle's E-Business Suite. The breach exploited a zero-day vulnerability between August 9-14, 2025, discovered by Cox on September 29, 2025. Approximately 6 New Hampshire residents were affected, with their names and Social Security numbers potentially exposed. Cox engaged forensic experts, applied security patches, and notified law enforcement. Affected individuals are offered credit monitoring services.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_244cea98a033cd5cTexas State AGfiled 2025-11-21Verified
- bd_76c8778cb9fa2c6dVermont State AGfiled 2025-11-20(1d gap)Verified
- bd_a35479fbdcf86c9aIndiana State AGfiled 2025-11-20(1d gap)Verified
- bd_c14447cb7482b2fdMaine State AGfiled 2025-11-20(1d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_d243eedeb344b5f2California State AGfiled 2025-11-20(1d gap)Verified
- bd_7369119a392f4428Montana State AGfiled 2025-11-25(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cox-enterprises-20251121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- 046186c3d72a092f9bfe9dd5119e291ce97f85162969204ca54bec61e4eb2179
Reporting entity
- Name
- COX ENTERPRISES, INC.norm: cox enterprises
Victim entity
- Name
- COX ENTERPRISES, INC.norm: cox enterprises
Incident
- Discovered
- Sep 29, 2025
- Materiality determined
- —
- Notification sent
- Nov 20, 2025
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.